Problem starting the Cisco 2821 router

Hello world

I have cisco 2821 router. I am facing problem starting.

someone suggest me what is the problem.

Thanks in advance...

VERSION of the SOFTWARE system Bootstrap, Version 12.4 (13r) T, (fc1)
Technical support: http://www.cisco.com/techsupport
Copyright (c) 2006 by cisco Systems, Inc.

The ECC memory initialization
.
C2821 platform of 262144 KB of main memory
Main memory is configured for 64-bit with ECC active

ReadOnly initialized ROMMON
load complete, point of entry to the program: 0x8000f000, size: 0xcb80
load complete, point of entry to the program: 0x8000f000, size: 0xcb80

load complete, point of entry to the program: 0x8000f000, size: 0x26bc2cc
Decompression of self-image: #.
################################################################################
################################################################################
################################################################################
################################################################################
################################################################# [OK]

Smart init is enabled
Smart init is sizing iomem
MEMORY_REQ TYPE ID
0003E8 0X003DA000 C2821 Mainboard
1A 0X0025178C E3 0001AB
0X00263F50 VPN on board
0X000021B8 embedded USB
Swimming pools public buffer 0X002C29F0
Swimming pools public particle 0 X 00211000
TOTAL: 0X00D65284

If all memory conditions above are
"UNKNOWN", you could use a non supported
configuration or there is a software problem and
the system may be compromised.
Rounded IOMEM to: 14 MB.
Using iomem of 5 percent. [14 mb / 256Mb]

Legend restricted rights

Use, duplication, or disclosure by the Government is
subject to such restrictions as set out in paragraph
(c) Commercial - limited computer software
The rights to FAR clause 52.227 - 19 and subparagraph s
(c) (1) (ii) rights to technical and computer data
Clause of DFARS 252.227 - 7013 section software.

Cisco Systems, Inc.
170 West Tasman Drive
San Jose, California 95134-1706

Cisco IOS software, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version 12.4 T7 (9)
Version of the SOFTWARE (fc3)
Technical support: http://www.cisco.com/techsupport
Copyright (c) 1986-2008 by Cisco Systems, Inc.
Last updated Friday, January 10 08 16:35 by prod_rel_team
Image text-base: 0x400B1E74 database: 0x434A9AC0

ERROR detected on Bus PCI1
Try REINSTALLING all the modules in the system
pci1_int_cause 0 x 00000240,
pci1_err_addr 0 x 00091009, pci0_err_cmd 0x0000000A
PCI Master Read parity error
Abort target PCI

R0 = r1 = r2 FFFFFFFF FFFFFFFF = 0 r3 = 45 80000 r4 = 0
R5 = 303 r6 = 0 A7 = 1 = 0 = 100000 r9 r8
R10 = 0 r11 = 465E4369 r12 = 0 r13 = 465E436A r14 = 0
R15 = r16 r17 8 = 0 = C100 r18 = 0 r19 3400 101 =
R20 = r21 0 = 40096828 r22 = FFFFFFFF r23 = r24 FFFF00FF = 0
R25 = 469AAC64 r26 = 0 = 469AAC60 r28 = 0 = 469AAC5C r29, r27
R30 = 0 r31 = 469AAC58 r32 = r33 FFFFFFFF = r34 = FFFFFFFF FFFFFFFF
R35 = r36 = r37 = r38 = r39 FFFFFFFF FFFFFFFF FFFFFFFF FFFFFFFF = FFFFFFFF
R40 = FFFFFFFF = FFFFFFFF = FFFFFFFF = FFFFFFFF r44 r43 r42 r41 = FFFFFFFF
R45 = r46 = r47 = r48 FFFFFFFF FFFFFFFF FFFFFFFF = r49 0 = 469AACD0
R50 = 0 0 = 0 r53 r51 = r52 = 3040A 801 r54 = FFFFFFFF
R55, r56 = FFFFFFFF = FFFFFFFF r58 r57 A000F000 = = 0 = 465E4358 r59
R60 = r61 = r62 FFFFFFFF FFFFFFFF = r63 = 0 402E4B10
GENS = 3400 103 mdlo_hi = my 0 = 251 00
mdhi_hi = 0 = 0 badvaddr_hi = FFFFFFFF mdhi
BadVAddr = cause = epc_hi 0 = FFFFFFFF FFFFFFFF
EPC = 402E4B08 err_epc_hi = err_epc FFFFFFFF = FFFFFFFF

ERR-1-FATAL %: interruption of the fatal error, reload
err_stat = 0 x 0

= Posts from Flushing (02: 37:51 UTC Wednesday, may 18, 2016) =.

Messages in queue:

02:37:51 UTC Wednesday, may 18, 2016: interrupt exception, signal CPU 22, PC = 0 x 0

--------------------------------------------------------------------
Software fault possible. On reccurence, you perceive
crashinfo, 'show tech' and contact Cisco Technical Support.
--------------------------------------------------------------------

-Trace =
$0: 00000000, AT: 00000000, v0: 00000000, v1: 00000000
A0: 00000000, a1: 00000000, a2: 00000000, a3: 00000000
T0: 00000000, t1: 00000000, t2: 00000000, t3: 00000000
T4: 00000000, t5: 00000000, t6: 00000000, t7: 00000000
s0: 00000000, s1: 00000000, s2: 00000000, s3: 00000000
S4: 00000000, s5: 00000000, s6: 00000000, s7: 00000000
T8: 00000000, t9: 00000000, k0: 00000000, k1: 00000000
GP: 00000000, sp: 00000000, s8: 00000000, ra: 00000000
EPC: 00000000, ErrorEPC: 00000000, GENS: 00000000
MY: 00000000, MDHI: 00000000, BadVaddr: 00000000
CacheErr: 00000000, DErrAddr0: 00000000, DErrAddr1: 00000000
DATA_START: 0X434A9AC0
Cause 00000000 (Code 0 x 0): Exception of interruption

Writing crashinfo in flash: crashinfo_20160518-023752
No reboot to warm storage
System received a system error *.
signal = 0 x 16, code = 0x0, context = 0 x 46905718
PC = 0x40096d7c, Cause = 0 x 20, State Reg = 0 x 34008002

Software Cisco IOS, 2800 Software (C2800NM-ADVIPSERVICESK9-M), Version 12.4 (9)T7
Version of the SOFTWARE (fc3)

OK, the router is running on a train of "T".

ERROR detected on Bus PCI1
Try REINSTALLING all the modules in the system
pci1_int_cause 0 x 00000240,
pci1_err_addr 0 x 00091009, pci0_err_cmd 0x0000000A
PCI Master Read parity error
Abort target PCI

Remove any all NM/NME or WIC/HWIC cards and restart again.  If the router is able to start properly, upgrade the router to a higher version.  DO NOT use another "T" train if it is needed.  Use instead a train of "M".

Tags: Cisco Support

Similar Questions

  • How to use Layer 2 Ports on the Cisco 1841 router switch

    Hello

    I use the Cisco 1841 router with a single port layer 3 Fe0 and 8 Ports switched.

    I gave the IP on the Fe0 port which is connected to another router.

    Now I don't know how to use Layer 2 of the router switch ports.

    I tried to make one of the port as a Port of access by switchport mode access and connected my laptop and the same subnet given IP, but I can't ping my Fe0 IP port and vice versa, as I am also unable to ping my laptop router.

    Can someone explain to me how to use these ports on layer 2?

    Hi Muhammadatifmasood, take a look at the link below, I'm sure that you will find it useful.

    https://supportforums.Cisco.com/discussion/10919631/how-enable-routing-b...

    BenSamayoa

  • LAN does not work when the Cisco E1000 router hangs

    Original title: Download sp3

    Remember - this is a public forum so never post private information such as numbers of mail or telephone! I bought recently a new Cisco E1000 router. My computer is a laptop model Lenovo 0769.

    I am running windows XP with sp2. The cisco software requires sp3. I called support of cisco and even they couldn't get to download sp3. My network is wireless on the router and I had to install from another laptop computer on the system. My LAN does not work when hooked. What do you suggest to me.

    Ideas:

    • You have problems with programs
    • Error messages
    • Recent changes to your computer
    • What you have already tried to solve the problem

    Hi mdenrique,

    1. what exactly do you mean by LAN (Local Area Network) does not work? You get the error message?

    If you have not installed Service Pack 3, try the following steps:
    Step 1: Download Service Pack 3
    see How to obtain the latest Windows XP service pack .
    b. scroll the window and click on "Download now the Windows XP Service Pack 3 package" to download the service pack.
    c. save the file on the desktop.

    Step 2: Install Service Pack 3
    a. open the file downloaded and follow the instructions in the wizard to complete the installation.
    b. restart the computer once the installation is complete.

    For more information, see steps to take before you install Windows XP Service Pack 3

    Note: Once you have installed service pack 3, install the router and check if the problem persists.

    Step 3: To troubleshoot LAN, run home and small Office Networking Troubleshooter
    a. Click Start and then click Help and Support.
    b. under Pick a help topic, click Network and Internet.
    c. under network and the Web, click on resolution of networking or Web problems and then click on home and small Office Networking convenience store.
    d. answer the questions in the troubleshooter to try to find a solution.

    For more information, see the following articles:
    1 see How to troubleshoot a network in Windows XP
    2 see two resources to solve the problems of connection network in Windows XP

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Having a problem starting the HP software for my officejet pro 8600

    When I try to start the program 8600 HP officejet screens pop - up.

    I can also scan is no longer the machine to my computer. can't I make changes to records of destination for faxes/scans.

    I can still

    I would like to do an uninstall of the software which is attached to this printer.

    I can't find the installation disk that came with it.

    Can I do an installation of your Web site to this site and get everything I need without the disc

    http://h10025.www1.HP.com/ewfrf/wc/softwareDownloadIndex?softwareitem=bi-108858-4&CC=CA&DLC=en&LC=en...

    Thanks in advance for the help

    Brek

    Hi Brek,

    Try to install the automatic fix below, I think that should solve the problem described:

    http://support.HP.com/us-en/document/c03640384

    If that helps you to uninstall software and put it back, since the link that you included above should do the trick.

    Please let me know of any changes,

    Shlomi

  • Problem with the Cisco VPN and Vista client

    Hello

    I have an easy VPN server configured on a c2811 and users use the Cisco VPN client. Lately, I have users running Windows Vista 64 bit and I need to know what is the correct version of the vpn client, I have to use and the compatibility problems with the server, I configured.

    Thank you and best regards.

    Cisco VPN Client doesn't have any version that is compatible with Vista 64 bit OS. The only customer that Cisco has released that supports the 64 bit OS's AnyConnect, but it is only supported on the CISCO ASA Appliance

  • Problem starting the Windows Media Player Media files

    I am using windows 7 Home Premium 64-bit on HP Probook 4530 s. These days, whenever I play any MP3, MP4 or any other media in windows media, the WMP player file starts the file, but the controls as start or pause button, volume control and screen WMP resized tool (arrows) crashes or jams for a few seconds and after the sound of "Gurk" (from the hard drive or dvd rom or I don't know where he's from) the control becomes normal. I played these with other software like VLC media player and other multimedia files, they do not have any sound and video or music plays well.

    You can solve this problem?
    Shalini thanks for noticing my question about WMP. But, before your response, I was able to solve this problem by myself.
    I used the clean windows troubleshooting tool for WMP and the detected problem was on the settings by default, but convenience store could not apply these settings.
    Later, I ran the tool troubleshooting in safe mode and the Troubleshoot utility managed to apply the default settings and the problem was solved.
  • PIX 6.3 SNMP MIB, problem with the CISCO-PROCESS compilation - MIB.oid

    I am Edgar Servín

    I have a cactus and got to watch the CPU of the PIX, I got the OID number:

    cpmCPUTotal5sec 1.3.6.1.4.1.9.9.109.1.1.1.1.3

    I used the Cisco SNMP Object Navigator and said:

    Compile the MIB

    Before you can compile CISCO-PROCESS-MIB, you need to compile the MIBS listed below in the order listed.

    Download all of these MIBs (WARNING: does not include non - Cisco MIB) or view details about each MIB below.

    How can I do?

    Hi Edgar,

    compiling the MIBs is necessary only when you are using HP OpenView or something similar. With the cactus, I confess that I have never used myself, but I'm pretty confident that you can just set the OID in Cacti and it will just make a periodic SNMP query for that object.

    HTH

    Herbert

  • Window7 & RaLink 802.11n & problem of the Netgear WPN824v2 router wireless connection

    Kevin Hau recommends a new thread to solve individual problems.  It's here.  In February 2010, I bought a new LG X 130 notebook with Windows 7 starter pre-installed.  On the first day, connection Wi - Fi was intermittent, although wired connection works well.  Links for laptop to a Netgear WPN824 V2 router.  This router has a wired to my PC and wireless for Toshiba laptop of my wife.  These work perfectly.  The latter two works on Win 7 Home Premium.

    I put WEP as a security measure for the router and wireless connections.  The LG X 130 connect wirelessly from a cold start about 25% of the time.  When it is not connected, no problems.  It should be necessary to restart, otherwise the computer expires then all that I get is "no connection is available" and there is absolutely no way to reconnect.  Cold boot does not work and the computer seems to need to set off for several days before it will condescend to connect again.

    Internet gives hundreds of 'my solutions' research which none appear not to work.  All the drivers are up to date and the latest versions.  I tried without security, WPA, WPA2, as some people suggest that 802.11n does not support WEP.  I tried b & g 108Mbps mode rather than by car.  All of these more recent attempts have failed to get any connection. On a recent trip away, the laptop could find the hotel network, but not connect to it.  He made a useful paper weight!

    The problem is clearly intermittent.  The laptop was returned twice to LG.  For the first time, they reinstalled everything, got a connection and returned.  The second time, they got a call and returned.  I can get connections, but I can't keep or make it reliable.

    Grateful for a solution.

    everything indicates material ralink or driver at this point... here, I had a
    best answer.
     
    On Tuesday, May 11, 2010 13:51:30 + 0000, n1mccabe wrote:
     
    >
    >
    > I tried a USB NIC 802.11 b/g/n with WPA2 AES and so far it connects without any problems. Aaaaarrgh! I tried to roll back the driver without success.
    >
    > That you for your time and patience on this one. It is appreciated. Seen little faith, however, it may be appropriate to keep this current thread at least for a little while.
    >
    >
     

    Barb Bowman www.digitalmediaphile.com

  • Problem starting the BIOS NB10t-A-101

    I just bought a NB10t to the United Kingdom and try to boot to a bootable USB key

    I noticed that the BIOS on this particular model is UEFI mode only, which, in itself, is not a problem because users can sign their own operating systems with a certification authority and use them, but this laptop refuses to boot from any external environment... or even to provide an error message.

    I changed boot priority in the BIOS and USB moved up
    I disabled the Secure Boot option in the BIOS
    I tried all 3 USB ports as well as 3 different drives (NOTE: THESE WORK FINE ON the 3 OTHER SYSTEMS, a dell desktop/laptop computer and a computer acer laptop)
    I also tried different distributions (Debian & Arch)
    I used several installation methods (hard install of Unetbootin/Full/Rufus etc...)
    I tried all your currently released BIOS versions (delivery with V1.0, V1.1 - Jan Feb - V1.2)

    After trying all these when you press F12 at startup, the shows start menu but when you select a device, the system continues to initiate (Win8) HARD drive
    After Googling around, I noticed that you have unlocked 2 BIOS updates I tried all versions of these and still the system refuses to boot in my selected device

    Can we expect more updates of the firmware in the near future? Is there a way to work around this problem to start my chosen OS? Is there an option of CSM?

    The laptop can be started from an external source such as USB flash memory stick but make sure of a few important points:
    A few tips:

    1 - USB key must be in the right port (USB2).
    2 - USB key must be UEFI-bootable (a Debian or Ubuntu, Installer copied on the USB stick with 'dd', is very well).
    3 - Bootloader file must be named boot/bootx64.efi (again, a picture of the Debian or Ubuntu installer will be already OK).
    4 - now try the ESC key before and during hit the power button, to select the boot device.

    Here, I found another thread on this topic:
    https://Forum.Toshiba.EU/showthread.php?75759

  • I can't open windows help and support. I get a message saying "windows cannot open help and support because a system service is running, to resolve this problem, start the service named help and support.

    How can I open help and support, I get a message telling me that I can't open it, as a system service runs not to solve the problem open help and support!

    How can I open help and support, I get a message telling me that I can't open it, as a system service runs not to solve the problem open help and support!

    Long time since I used XP but I seem to remember that if you do start - run msconfig [back] in my view, there are Services tab there where you can change the aid stopped service to start.

    If you find my answer helpful, please click the button "Vote as helpful"! Thank you! My Blog

  • Problem with the cisco 5510 port mapping

    Hello

    My device Cisco ASA 5510, ASA 8.4 (2), 6.4 AMPS (5) 206

    What I'm trying to achieve.

    (1) listening host 10.10.11.108 port 8080

    (2) trying to access from WAN for example port 8090

    I tried command sequence:

    Network 10.10.11.108_8080 object
    Home 10.10.11.108
    NAT (LAN1, WAN) interface static 8080-8090 tcp service

    allowed to Access - list line extended 11 tcp WAN_access_in any object eq 10.10.11.108_8080 8080
    WAN_access_in access to the WAN interface group

    But I do not have access gett. Can someone help me to solve this case?

    I think I know what the problem is:

    object service tcp-8080 service tcp destination eq 8080 object service tcp-8090 service tcp destination eq 8090 
    change to the source destination:
    object service tcp-8080 service tcp source eq 8080 object service tcp-8090 service tcp source eq 8090 
    
    
    no access-list WAN_access_in extended permit object tcp-8080 any object 10.10.11.108_8080 
    access-list WAN_access_in extended permit tcp any object 10.10.11.108_8080 eq 8080
    -Please do not forget to select a correct answer and rate useful posts
  • Problem with the Cisco ASA 5525 X SFR and Firesight high school

    Hi team,

    We have two ASA 5525 X installed on them and Firesight in a Linux VM whose two SFRs are registered with SFR failover mode. We use the SAA secondary off the hook if the primary fails to turn on the secondary manually switch the wan cable. I turn on the ASA secondary every weekend to take the configuration of the primary for the ASA and the SFR and close by button walk / stop.

    Last week I turn on high school ASA and the Firesight couldn't see the secondary SFR and show the message below:

    Module device heartbeat: device > don't send heartbeats.

    (I should mention I can Pinger the IP ADDRESS)

    I tried to study the problem without success.

    I also deleted the sensor just Firesight devices management in case something is stuck, and I'm trying to re added without success.

    I'm new in firepower so... any ideas?

    Thank you

    Finally, this problem has been resolved by the redefinition of firepower:

    see detailed here procedure to perform this redefinition;

    http://www.Cisco.com/c/en/us/support/docs/security/ASA-firepower-service...

    Before that, it appeared that firepower was not very healthy:

    After a success "" configure Manager add xxxxx"command.

    the command of managers show show nothing;

    He should have shown this result:

    > Display managers
    Host: 193.193.2.75
    Registration key: AZERTY
    Inscription: pending
    State of the PRC:

    on the other hand, in expert mode, the following command shows several processes (and not in the normal state):

    sudo pmtool status | grep-i down

    Last point,

    After the recreation and reconfigure all this fire power, installed in the ASA secondary standby, was considered to be OK under Firesight health Monitor,.

    but after 10mins, it appeared in critical condition with the following message:

    "Interface"DataPlaneInterface0"receives not all packages.

    This is normal and due to the fact that Eve ASA receives no flow and the same goes for firepower inside this ASA;

    by performing a failover from the primary to the secondary ASA, this critical message disappeared for firepower inside the ASA Sec and appeared for firepower inside the ASA elementary school

  • Supported on the Cisco RV042 router settings

    Hello

    Anyone know if these settings are supported on router CiscoRV042

    shared secret - authentication-

    -AES-256 / SHA1 encryption

    -IKE: Diffie-Hellman (Group 2)

    -Phase 1 IKE every 1440 minutes.

    -The phase 2 (IPsec) all 3600 sec (every hour) of IKE

    Thank you.

    These are all very standard parts of IPSEC.

    See page 45 of the

    http://www.Cisco.com/en/us/docs/routers/CSBR/RV042/Admin/Guide/RV042_V10_UG_C-Web.PDF

    Copied here

    IPSec configuration

    So that any encryption occur, both ends of a

    VPN tunnel must agree on the encryption methods,

    decryption and authentication. This is done by sharing

    a key for the encryption code. Key management, the

    default mode is IKE with pre-shared key.

    Overlay Mode Select IKE with pre-shared key or manual.

    Both ends of a VPN tunnel must use the same mode of

    key management. After selecting the mode, the

    settings available on this screen may change depending

    on the selection you have made. Follow the instructions

    for the mode you want to use. (Manual mode is available

    for VPN tunnels only, no VPN group.)

    IKE with preshared key

    IKE is used to negotiate Internet Key Exchange Protocol

    for Security Association (SA) key material. IKE use it

    Pre-shared key for authentication to the remote peer of IKE.

    The phase 1 DH group Phase 1 is used to create the SA. DH

    (Diffie-Hellman) is a key exchange protocol used for

    Phase 1 of the authentication before establishing process

    pre-shared keys. There are three groups of different premium

    length of the key. Group 1 is 768 bits, and group 2 is 1024 bits.

    Group 5 is 1 536 bits. If the network speed is preferred, select

    Group 1. If it is better to network security, select group 5.

    The phase 1 encryption select an encryption method: SOME

    (56-bit), 3DES (168-bit), AES-128 (128-bit), AES-192 (192-

    ILO) or AES-256 (256-bit). The method determines the

    length of the key used to encrypt or decrypt ESP packets

    AES - 256 is recommended because it is the safest.

    Make sure that both ends of the VPN tunnel using the same

    encryption method.

    The phase 1 authentication select a method of

    authentication, MD5 or SHA. The authentication method

    determines how the ESP packets are validated. MD5 is

    a one-way hash algorithm that produces a 128-bit

    Digest. SHA is a one-way hashing algorithm which produces

    a 160-bit digest. SHA is recommended because it is more

    Fix. Make sure that both ends of the VPN tunnels using the

    same authentication method.

    Phase 1 life time sets the duration of a VPN

    tunnel is active in Phase 1. The default is 28800

    seconds.

    Perfect Forward Secrecy if the perfect forward secrecy

    (PFS) is enabled, the IKE Phase 2 negotiation will be

    generate new key material for encryption of IP traffic and

    authentication, then pirates using brute force to break

    encryption keys will not be able to obtain future IPSec

    keys.

    Phase 2 DH group if the functionality of perfect forward secrecy

    is disabled, then no new key will be generated, so you don't have

    no need to adjust the Phase 2 DH group (the key for Phase 2

    will be the key in Phase 1).

    There are three groups of different main key lengths.

    Group 1 is 768 bits, and group 2 is 1024 bits. Group 5 is

    1 536 bits. If the network speed is preferred, select group 1.

    If it is better to network security, select group 5. You do

    no need to use the same group of DH that you used for

    Phase 1.

    Encryption of the phase 2 Phase 2 is used to create an or

    several IPSec security associations, which are then used to key IPSec sessions.

    Select an encryption method: NULL, (56-bit), 3DES

    (168 bit), AES-128 (128-bit), AES-192 (192-bit) or AES-

    256 (256-bit). It determines the length of the key used to

    encrypt or decrypt packets ESP. AES-256 is recommended

    because it is the safest. Both ends of the VPN tunnel

    must use the same encryption of Phase 2 setting.

    The phase 2 authentication select a method of

    authentication, NULL, MD5 or SHA. Authentication

    method determines how the ESP packets are validated.

    MD5 is a one-way hash algorithm that produces a

    Digest of 128 bits. SHA is a one-way hashing algorithm that

    produces a 160-bit "Digest". SHA is recommended because

    It's safer. Both ends of the VPN tunnel must use

    the same Phase 2 authentication setting.

    Phase 2 HIS life time sets the duration of a VPN

    tunnel is active in Phase 2. The default value is 3600 seconds.

    Pre-shared key that specifies the pre-shared key used

    to authenticate the remote peer of IKE. Enter a key of

    keyboard and hexadecimal characters, for example, [email protected]/ * /.

    or 4d795f40313233. This field allows a maximum of 30

    characters and hexadecimal values. The two ends of the

    the VPN tunnel must use the same pre-shared key. It's

    We recommend that you change the pre-shared

    Key periodically in order to maximize the VPN security.

  • ASA problem inside the VPN client routing

    Hello

    I have a problem where I can't reach the VPN clients with their vpn IP pool from the inside or the asa itself. Connect VPN clients can access internal network very well. I have no nat configured for the pool of vpn and packet trace crypt packages and puts it into the tunnel. I'm not sure what's wrong.

    Here are a few relevant config:

    network object obj - 192.168.245.0

    192.168.245.0 subnet 255.255.255.0

    192.168.245.1 - 192.168.245.50 vpn IP local pool

    NAT (inside, outside) static source any any destination static obj - 192.168.245.0 obj - 192.168.245.0 no-proxy-arp-search to itinerary

    Out of Packet trace:

    Firewall # entry packet - trace inside the x.x.x.x icmp 8 0 192.168.245.33

    Phase: 1

    Type: ACCESS-LIST

    Subtype:

    Result: ALLOW

    Config:

    Implicit rule

    Additional information:

    MAC access list

    Phase: 2

    Type:-ROUTE SEARCH

    Subtype: entry

    Result: ALLOW

    Config:

    Additional information:

    in 192.168.245.33 255.255.255.255 outside

    Phase: 3

    Type: ACCESS-LIST

    Subtype: Journal

    Result: ALLOW

    Config:

    Access-group acl-Interior interface inside

    access list acl-Interior extended icmp permitted an echo

    Additional information:

    Phase: 4

    Type: IP-OPTIONS

    Subtype:

    Result: ALLOW

    Config:

    Additional information:

    Phase: 5

    Type: INSPECT

    Subtype: np - inspect

    Result: ALLOW

    Config:

    Additional information:

    Phase: 6

    Type:

    Subtype:

    Result: ALLOW

    Config:

    Additional information:

    Phase: 7

    Type: NAT

    Subtype:

    Result: ALLOW

    Config:

    NAT (inside, outside) static source any any destination static obj - 192.168.245.0

    obj - 192.168.245.0 no-proxy-arp-search to itinerary

    Additional information:

    Definition of static 0/x.x.x.x-x.x.x.x/0

    Phase: 8

    Type: VPN

    Subtype: encrypt

    Result: ALLOW

    Config:

    Additional information:

    Phase: 9

    Type: CREATING STREAMS

    Subtype:

    Result: ALLOW

    Config:

    Additional information:

    New workflow created with the 277723432 id, package sent to the next module

    Result:

    input interface: inside

    entry status: to the top

    entry-line-status: to the top

    output interface: outside

    the status of the output: to the top

    output-line-status: to the top

    Action: allow

    There is no route to the address pool of vpn. Maybe that's the problem? I don't know than that used to work before we went to 8.4.

    Check if the firewall is enabled on your host from the client ravpn and blocking your pings.

  • Problem with the Cisco ASA vpn redundancy?

    Hi all

    I have a series ASA 5500 firewall and need to set a different peer ip for the connection of site2sitevpn. In fact, my goal is, ASA tent first pair ip of the site2site tunnel, when ASA may not reach this ip, try to reach another ip I set before. I can configure this scenerio on Cisco router with this command;


    crypto map tohub 1 ipsec-isakmp
     set peer 10.1.1.1 default 
     set peer 10.2.2.2

    but I wonder what can I do about ASA?

    Thank you.

    Best regards.

    Shane,

    You can configure multiple IP addresses, under the same entry of homologous set on ASA, but it works the same on IOS with preferred peer, it passes between defined peer.

    Marcin

Maybe you are looking for